First obligations from September 2026
Component & Supplier Assessment

Supply chain security with a supplier portal and structured assessment

Vendor management, a pre-built CRA framework, and a self-service portal that requires no supplier account

Art. 13(5) of the EU Cyber Resilience Act requires manufacturers to exercise due diligence when integrating third-party components. With the supplier portal you send a request by email. The supplier opens a Magic-Link, answers 14 CRA criteria, uploads evidence, and submits. No account, no password. You review every answer in the compare view and decide per criterion: accept or reject.

Art. 13(5)Legal basis
Magic-LinkNo login required
14 criteriaCRA framework
Accept/RejectReview
app.kunnus.tech/compliance/requests/jane.doe@smart-systems.com
Supplier request

jane.doe@smart-systems.com

Submitted
13 Accepted1 Rejected0 Pending review
Information Security Policy
Does the vendor have a documented information security policy?
Your current value
Supplier proposed
Yes
Security_Policy_v1.pdf
You'll find the policy in the attachment.
Security Certifications
What security certifications does the vendor hold?
Your current value
Supplier proposed
ISO 27001
You selected ISO 27001, but haven't uploaded any evidence.
Vulnerability Disclosure Policy
Does the vendor have a public vulnerability disclosure policy?
Your current value
Supplier proposed
Yes

Key Benefits

Magic-Link Requests

Send compliance requests by email. Suppliers respond via a secure Magic-Link. No account, no password, no friction.

Compare & Review Workflow

You see your current value next to the supplier's proposal and accept or reject individual answers. All in one compare view.

Evidence Upload in the Portal

Suppliers upload policies, certificates (ISO 27001, SOC 2, TISAX), and documents directly in the portal. Required evidence is enforced before submission.

Pre-Built CRA Framework

The CRA Vendor Security Assessment framework covers 14 criteria: from Information Security Policy and Vulnerability Disclosure to Incident Response Plan. Configurable per supplier.

Capabilities

Self-Service Supplier Portal with Magic-Link

Live since June 2026

Suppliers respond to requests via a one-time Magic-Link without creating an account. Sidebar navigation through every criterion, autosave, mandatory evidence, and a submit confirmation.

Compare View & Accept/Reject per Criterion

Art. 13

For each criterion you see your current value alongside the supplier's proposal. Accept individual answers, reject with a comment, or request changes.

CRA Vendor Security Assessment

Pre-built assessment framework with 14 criteria specifically for CRA-compliant vendor evaluation. Ready to use with configurable criteria.

Component Assessment

Individual components are assessed in a structured way too — with risk levels, evidence upload, and review workflow, integrated into the component library.

Central Vendor Management

Complete vendor data with one-click import of common vendors. Supply chain risk overview with prioritization based on criticality of supplied components.

Use Cases

01

Magic-Link Request to a Supplier

The compliance manager sends a request with 14 CRA criteria to a supplier. They click the Magic-Link, fill out the portal, upload evidence, and submit. Without creating an account.

02

Review with Accept/Reject per Criterion

The manufacturer reviews the supplier's answers in the compare view and accepts 13 criteria. The security certifications lack evidence: rejection with a comment — the supplier automatically receives a fresh Magic-Link to correct it.

03

Initial Vendor Onboarding

A manufacturer imports their 50 most important vendors via one-click import and immediately starts with the CRA Vendor Security Assessment framework.

04

Audit Evidence for Supply Chain Security

Auditors receive structured evidence of all vendor evaluations — including evidence, risk levels, and review history.

Secure your supply chain systematically

See how Kunnus connects vendor assessment and supply chain security. We'll walk you through the workflow in a personalized demo.